Trax.Api.Auth 1.44.1

Prefix Reserved
There is a newer version of this package available.
See the version list below for details.
dotnet add package Trax.Api.Auth --version 1.44.1
                    
NuGet\Install-Package Trax.Api.Auth -Version 1.44.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Trax.Api.Auth" Version="1.44.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Trax.Api.Auth" Version="1.44.1" />
                    
Directory.Packages.props
<PackageReference Include="Trax.Api.Auth" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Trax.Api.Auth --version 1.44.1
                    
#r "nuget: Trax.Api.Auth, 1.44.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Trax.Api.Auth@1.44.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Trax.Api.Auth&version=1.44.1
                    
Install as a Cake Addin
#tool nuget:?package=Trax.Api.Auth&version=1.44.1
                    
Install as a Cake Tool

Trax.Api authentication and audit

Security disclaimer: read this first

NO WARRANTY FOR SECURITY. Trax.Api.Auth and Trax.Api.GraphQL.Audit are provided AS-IS. Trax, its authors, and contributors are NOT LIABLE for any security breach, credential leak, data loss, or damage arising from systems built on top of these packages. Securing your deployment is the SOLE RESPONSIBILITY OF THE CONSUMER.

Trax auth is plumbing, not a security product. It does not vet the strength of your keys, rotate secrets, detect compromised credentials, enforce TLS, rate-limit abusers, detect replay attacks, or threat-model on your behalf, and it is not a substitute for a professional security review. MIT's NO WARRANTY clause is not a formality: if your deployment is breached, the fault and the fix are yours.

The full disclaimer, including the consumer responsibility checklist, ships in this package as SECURITY-DISCLAIMER.md and is on GitHub: SECURITY-DISCLAIMER.md. Read it before you deploy.

What these packages are

Trax is a .NET framework for building trains (typed pipelines of junctions) with execution logging, scheduling and a GraphQL API. These packages connect ASP.NET Core authentication to the Trax GraphQL API (Trax.Api.GraphQL): every scheme projects the caller into a TraxPrincipal, which [TraxAuthorize] on a train checks and which junctions can inject.

Package What it does Reference
Trax.Api.Auth TraxPrincipal, ITraxPrincipalResolver<T> and the claim-type constants every scheme shares. Referenced by the scheme packages. TraxPrincipal
Trax.Api.Auth.ApiKey Header-based API keys (X-Api-Key by default), salted and hashed at startup. AddTraxApiKeyAuth
Trax.Api.Auth.Jwt JWT bearer tokens, validated by Microsoft.AspNetCore.Authentication.JwtBearer. AddTraxJwtAuth
Trax.Api.Auth.Jwt.Cognito UseCognito(...) on the JWT builder: Amazon Cognito ID and access tokens and their claims. UseCognito
Trax.Api.Auth.Jwt.Cognito.Issuer Mints Cognito-shaped RS256 tokens, with a refresh-token store contract. Cognito issuer
Trax.Api.Auth.Jwt.Testing A self-hosted JWKS server and token minters for integration tests. JWT testing
Trax.Api.Auth.Oidc OpenID Connect code flow with PKCE and a session cookie, for browser sign-in. AddTraxOidcAuth
Trax.Api.GraphQL.Audit Records each GraphQL request to your ITraxAuditSink from a bounded channel and a background writer. API Security

Installation

dotnet add package Trax.Api.GraphQL
dotnet add package Trax.Api.Auth.ApiKey    # or Trax.Api.Auth.Jwt, Trax.Api.Auth.Oidc
dotnet add package Trax.Api.GraphQL.Audit  # optional

Example

An API-key scheme and a JWT scheme on one host, the GraphQL endpoint gated on either, and every request audited:

using Trax.Api.Auth.ApiKey;
using Trax.Api.Auth.Jwt;
using Trax.Api.GraphQL.Audit;
using Trax.Api.GraphQL.Extensions;
using Trax.Effect.Data.Postgres.Extensions;
using Trax.Effect.Extensions;
using Trax.Mediator.Extensions;

var builder = WebApplication.CreateBuilder(args);

builder.Services.AddTrax(trax =>
    trax.AddEffects(effects => effects.UsePostgres(connectionString))
        .AddMediator(typeof(Program).Assembly)
);

// Keys come from your secret manager, never from source control.
builder.Services.AddTraxApiKeyAuth(keys => keys
    .Add(builder.Configuration["ApiKeys:Admin"]!, id: "admin", "Admin"));

builder.Services.AddTraxJwtAuth(jwt => jwt.UseAuthority(
    authority: "https://login.example.com",
    audience: "my-api"));

builder.Services.AddAuthorization();

// With no policy name, RequireAuthorization uses TraxAuthClaimTypes.TraxAuthPolicy, which
// every AddTrax*Auth call adds its scheme to: an API key or a JWT is accepted.
builder.Services.AddTraxGraphQL(graphql => graphql
    .RequireAuthorization()
    .AddAudit<MyAuditSink>());

var app = builder.Build();

app.UseAuthentication();
app.UseAuthorization();
app.UseTraxGraphQL();   // maps at /trax/graphql

app.Run();

public sealed class MyAuditSink : ITraxAuditSink
{
    public Task WriteAsync(IReadOnlyList<TraxAuditEntry> batch, CancellationToken ct)
    {
        // Persist the batch. Redact sensitive variables first with an ITraxAuditRedactor.
        return Task.CompletedTask;
    }
}

Per-train authorization uses [TraxAuthorize] on the train class; see Authorization. Subscriptions carry credentials in the connection_init payload; see API Security.

Documentation

License

MIT, with the security disclaimer above. See LICENSE.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (5)

Showing the top 5 NuGet packages that depend on Trax.Api.Auth:

Package Downloads
Trax.Api.GraphQL

GraphQL API for Trax on HotChocolate: runs and queues trains, exposes executions, manifests and the work queue, and generates queries from [TraxQueryModel] entities. Install it to give a Trax host a GraphQL endpoint (AddTraxGraphQL, UseTraxGraphQL).

Trax.Api.Auth.Jwt

JWT bearer authentication scheme for Trax: thin wrapper over Microsoft.AspNetCore.Authentication.JwtBearer that projects validated tokens into a TraxPrincipal. NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See SECURITY-DISCLAIMER.md.

Trax.Api.Auth.ApiKey

API-key authentication for the Trax GraphQL API: an X-Api-Key header handler with salted, hashed keys, registered with AddTraxApiKeyAuth. Install to authenticate service-to-service callers. NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See SECURITY-DISCLAIMER.md.

Trax.Api.GraphQL.Audit

Request-level audit pipeline for the Trax GraphQL API: a bounded-channel listener and background batch writer that hand each request to your ITraxAuditSink, registered with AddAudit on the GraphQL builder. NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See SECURITY-DISCLAIMER.md.

Trax.Api.Auth.Oidc

OpenID Connect authentication scheme for Trax: code flow with PKCE, session cookie, and a resolver hook that projects ID-token claims into a TraxPrincipal. NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See SECURITY-DISCLAIMER.md.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.45.0 54 10/2/2026
1.44.2 82 10/1/2026
1.44.1 222 9/29/2026
1.44.0 109 9/29/2026
1.43.2 521 9/24/2026
1.43.1 1,422 9/16/2026
1.43.0 171 9/16/2026
1.42.0 1,653 9/15/2026
1.41.1 1,016 9/2/2026
1.41.0 198 9/2/2026
1.40.0 407 7/29/2026
1.39.0 413 7/8/2026
1.38.1 2,160 7/6/2026
1.38.0 1,428 6/2/2026 1.38.0 is deprecated because it has critical bugs.
1.37.0 496 6/2/2026 1.37.0 is deprecated because it has critical bugs.
1.36.0 249 6/2/2026 1.36.0 is deprecated because it has critical bugs.
1.35.0 274 6/1/2026 1.35.0 is deprecated because it has critical bugs.
1.34.1 746 5/21/2026
1.34.0 208 5/21/2026
1.33.0 263 5/19/2026
Loading failed

NO WARRANTY. Trax auth is plumbing, not a security product. You are solely responsible for securing systems that use it. See SECURITY-DISCLAIMER.md.